2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42924 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the... |
| CVE-2025-42919 | MEDIUM | 5.3 | 0.4% | Nov 11, 2025 | Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b... |
| CVE-2025-42899 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting ... |
| CVE-2025-42897 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal... |
| CVE-2025-42895 | MEDIUM | 6.9 | 0.1% | Nov 11, 2025 | Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a... |
| CVE-2025-42894 | MEDIUM | 6.8 | 0.3% | Nov 11, 2025 | Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adja... |
| CVE-2025-42893 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL... |
| CVE-2025-42892 | MEDIUM | 6.8 | 0.9% | Nov 11, 2025 | Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac... |
| CVE-2025-42889 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end... |
| CVE-2025-42888 | MEDIUM | 5.5 | 0.1% | Nov 11, 2025 | SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information... |
| CVE-2025-42886 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could... |
| CVE-2025-42885 | MEDIUM | 5.8 | 0.3% | Nov 11, 2025 | Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled functio... |
| CVE-2025-42884 | MEDIUM | 6.5 | 0.2% | Nov 11, 2025 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL u... |
| CVE-2025-42882 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic ... |
| CVE-2025-31719 | MEDIUM | 5.1 | 0.1% | Nov 11, 2025 | In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature r... |
| CVE-2025-64529 | MEDIUM | 6.5 | 0.2% | Nov 10, 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio... |
| CVE-2025-64504 | MEDIUM | 5 | 0.3% | Nov 10, 2025 | Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2... |
| CVE-2025-64502 | MEDIUM | 6.9 | 0.4% | Nov 10, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `exp... |
| CVE-2025-64167 | MEDIUM | 6.1 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-sit... |
| CVE-2025-63397 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence ... |
| CVE-2025-62780 | MEDIUM | 5.4 | 0.4% | Nov 10, 2025 | changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in cha... |
| CVE-2025-49145 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough ri... |
| CVE-2025-63617 | MEDIUM | 6.5 | 0.2% | Nov 10, 2025 | ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulne... |
| CVE-2025-63296 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot... |
| CVE-2025-48878 | MEDIUM | 4.3 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now